THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-pm5p-7w5h-jm5q (low) — Easy!Appointments has server-side request forgery in CalDAV connection test that exposes the deployment's internal network

[GHSA] GHSA-pm5p-7w5h-jm5q (low) — Easy!Appointments has server-side request forgery in CalDAV connection test that exposes the deployment's internal network

highgithub_advisoriesPublished 2026-07-29

GHSA-pm5p-7w5h-jm5q Severity: low CVE: CVE-2026-52840

Easy!Appointments has server-side request forgery in CalDAV connection test that exposes the deployment's internal network

### Summary

`Caldav::connect_to_server` at `application/controllers/Caldav.php:60` hands the request's `caldav_url` to a Guzzle `REPORT` call without scheme or host validation. A logged-in backend user (admin, provider,

Indicators of compromise

Original source: https://github.com/advisories/GHSA-pm5p-7w5h-jm5q